Post-Java, Post-Norton OTL Log 2
========== Files - Modified Within 30 Days ==========
[2010/12/16 22:29:02 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/16 22:05:50 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/16 22:05:46 | 000,001,192 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2010/12/16 22:05:31 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2010/12/16 22:05:30 | 535,875,584 | -HS- | M] () -- C:\hiberfil.sys
[2010/12/16 21:48:01 | 000,001,030 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1380815714-836596746-3658294935-1008UA.job
[2010/12/16 21:12:17 | 000,205,540 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\JavaRa.zip
[2010/12/16 20:49:45 | 000,924,816 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Norton_Removal_Tool.exe
[2010/12/16 20:48:01 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1380815714-836596746-3658294935-1008Core.job
[2010/12/16 20:45:32 | 000,002,361 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/12/16 20:45:31 | 000,002,383 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Google Chrome.lnk
[2010/12/16 18:33:02 | 000,018,944 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\Kingdoms.xls
[2010/12/15 20:14:26 | 000,000,595 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WNA3100 Smart Wizard.lnk
[2010/12/15 20:14:26 | 000,000,583 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\NETGEAR WNA3100 Smart Wizard.lnk
[2010/12/14 20:42:46 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\ETC\hosts
[2010/12/13 11:43:58 | 003,989,182 | R--- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\ComboFix.exe
[2010/12/10 21:22:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/12/10 11:49:50 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\MBRCheck.exe
[2010/12/10 11:49:06 | 001,230,779 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\tdsskiller.zip
[2010/12/08 14:48:08 | 001,344,600 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Samuel M. Saunders\Desktop\TDSSKiller.exe
[2010/12/07 21:27:23 | 000,040,960 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Avira AntiVir Personal.doc
[2010/12/07 11:07:38 | 000,132,597 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Flash_Disinfector.exe
[2010/12/07 11:03:32 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Samuel M. Saunders\Desktop\TFC.exe
[2010/12/06 14:44:32 | 000,296,448 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\r86rzteq.exe
[2010/12/06 14:39:26 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Samuel M. Saunders\Desktop\OTL.exe
[2010/12/06 11:26:06 | 000,002,473 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\HiJackThis.lnk
[2010/12/04 19:27:34 | 000,273,376 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/04 18:49:12 | 000,000,316 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2010/12/04 18:38:23 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2010/12/04 17:48:43 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2010/12/04 17:25:59 | 000,004,444 | ---- | M] () -- C:\WINDOWS\System32\pid.PNF
[2010/12/04 17:25:48 | 000,422,722 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
[2010/12/04 17:25:48 | 000,071,186 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
[2010/11/29 17:42:18 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/11/22 16:49:27 | 000,271,360 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\contacts.pst
[1 C:\Documents and Settings\Samuel M. Saunders\*.tmp files -> C:\Documents and Settings\Samuel M. Saunders\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/16 21:12:31 | 000,205,540 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\JavaRa.zip
[2010/12/16 20:52:56 | 000,924,816 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Norton_Removal_Tool.exe
[2010/12/16 20:45:32 | 000,002,361 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/12/16 20:45:31 | 000,002,383 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Google Chrome.lnk
[2010/12/16 20:43:37 | 000,001,030 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1380815714-836596746-3658294935-1008UA.job
[2010/12/16 20:43:36 | 000,000,978 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1380815714-836596746-3658294935-1008Core.job
[2010/12/15 20:14:26 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2010/12/15 20:14:26 | 000,000,595 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WNA3100 Smart Wizard.lnk
[2010/12/15 20:14:26 | 000,000,583 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\NETGEAR WNA3100 Smart Wizard.lnk
[2010/12/14 20:50:26 | 535,875,584 | -HS- | C] () -- C:\hiberfil.sys
[2010/12/13 18:24:07 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/12/13 18:24:07 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/12/13 18:24:07 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/12/13 18:24:07 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/12/13 18:24:07 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/12/13 18:18:09 | 003,989,182 | R--- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\ComboFix.exe
[2010/12/10 12:44:28 | 000,080,384 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\MBRCheck.exe
[2010/12/10 12:35:34 | 001,230,779 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\tdsskiller.zip
[2010/12/07 21:27:23 | 000,040,960 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Avira AntiVir Personal.doc
[2010/12/07 19:12:04 | 000,296,448 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\r86rzteq.exe
[2010/12/07 18:51:16 | 000,132,597 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Flash_Disinfector.exe
[2010/12/06 13:13:51 | 000,018,944 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xrxscnui.dll
[2010/12/06 13:13:48 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xrxftplt.exe
[2010/12/06 13:02:03 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2010/12/06 12:55:51 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2010/12/06 12:54:42 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2010/12/06 12:54:39 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2010/12/06 12:54:34 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2010/12/06 12:53:36 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2010/12/06 12:52:42 | 000,165,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt53.dll
[2010/12/06 12:52:38 | 000,093,696 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt42.dll
[2010/12/06 12:52:33 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt34.dll
[2010/12/06 12:52:28 | 000,089,088 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt33.dll
[2010/12/06 12:52:24 | 000,083,968 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt21.dll
[2010/12/06 12:52:07 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2010/12/06 12:51:28 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
[2010/12/06 12:49:19 | 000,029,768 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divasu.dll
[2010/12/06 12:49:18 | 000,037,962 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divaprop.dll
[2010/12/06 12:49:17 | 000,006,216 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divaci.dll
[2010/12/06 12:47:37 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2010/12/06 12:46:17 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atixbar.sys
[2010/12/06 12:46:16 | 000,026,624 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativxbar.sys
[2010/12/06 12:46:16 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativttxx.sys
[2010/12/06 12:46:15 | 000,009,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativmdcd.sys
[2010/12/06 12:46:14 | 000,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitvsnd.sys
[2010/12/06 12:46:14 | 000,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitunep.sys
[2010/12/06 12:46:13 | 000,049,920 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtcap.sys
[2010/12/06 12:46:13 | 000,026,880 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtsnd.sys
[2010/12/06 12:46:11 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atipcxxx.sys
[2010/12/06 12:46:04 | 000,046,464 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atibt829.sys
[2010/12/06 11:25:46 | 000,002,473 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\HiJackThis.lnk
[2010/12/04 17:25:59 | 000,004,444 | ---- | C] () -- C:\WINDOWS\System32\pid.PNF
[2010/12/04 17:25:09 | 000,144,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat
[2010/12/04 17:25:09 | 000,014,433 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn9.cat
[2010/12/04 17:25:08 | 000,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2010/12/04 17:25:08 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2010/12/04 17:25:08 | 000,112,918 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat
[2010/12/04 17:25:08 | 000,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2010/12/04 17:25:08 | 000,034,747 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat
[2010/12/04 17:25:08 | 000,034,063 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
[2010/12/04 17:25:08 | 000,026,991 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn7.cat
[2010/12/04 17:25:08 | 000,016,535 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
[2010/12/04 17:25:08 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2010/12/04 17:25:08 | 000,012,363 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2010/12/04 17:25:08 | 000,010,027 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2010/12/04 17:25:08 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2010/12/04 17:25:08 | 000,007,710 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2010/12/04 17:25:08 | 000,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat
[2010/12/04 17:25:07 | 002,144,487 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
[2010/12/04 17:25:07 | 001,296,669 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP3.CAT
[2010/12/04 17:25:07 | 000,522,220 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2009/09/28 04:02:05 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2009/08/13 07:11:17 | 000,019,350 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\kevik.bin
[2009/08/13 07:11:16 | 000,018,923 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Application Data\raqivyv._dl
[2009/08/13 07:11:16 | 000,013,308 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Application Data\lokafoje.bin
[2009/08/03 12:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/02/10 12:25:30 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2009/02/10 12:23:49 | 000,000,044 | ---- | C] () -- C:\WINDOWS\EPSNX400.ini
[2008/04/13 21:42:04 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2007/09/13 18:04:35 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MTB13GE.INI
[2007/02/23 16:52:26 | 000,002,508 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Application Data\$_hpcst$.hpc
[2007/01/10 05:18:18 | 000,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
[2006/07/03 04:25:16 | 000,000,036 | ---- | C] () -- C:\WINDOWS\webica.ini
[2005/12/26 16:54:59 | 000,001,787 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/12/16 08:51:15 | 000,000,387 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2005/11/01 10:06:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2005/02/10 10:17:50 | 000,172,056 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll
[2004/07/13 17:40:39 | 000,011,142 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
[2004/07/04 04:17:40 | 000,000,700 | ---- | C] () -- C:\WINDOWS\MTB13.INI
[2004/05/23 04:06:18 | 000,207,360 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/05/19 08:58:26 | 000,000,141 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Local Settings\Application Data\fusioncache.dat
[2004/05/13 21:30:05 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/05/13 21:18:33 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/05/13 21:08:18 | 000,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2004/05/13 20:48:54 | 000,000,550 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/01/23 06:03:50 | 000,000,791 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
[2003/01/07 12:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/09/03 10:35:18 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[1979/12/31 21:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
========== LOP Check ==========
[2008/07/18 06:19:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bloomberg
[2009/02/10 12:36:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2010/08/20 09:02:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/12/14 19:15:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/20 17:46:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/06/25 03:09:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/23 06:22:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/06/18 12:40:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/08/20 07:29:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Samuel M. Saunders\Application Data\Aim
[2006/05/13 05:11:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Samuel M. Saunders\Application Data\ICAClient
[2010/08/20 08:12:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Samuel M. Saunders\Application Data\Juniper Networks
[2005/09/02 06:29:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Samuel M. Saunders\Application Data\Leadertech
[2010/12/14 19:15:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Samuel M. Saunders\Application Data\Viewpoint
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2002/09/03 10:36:02 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010/12/04 17:48:43 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2002/09/03 10:13:28 | 000,000,512 | -HS- | M] () -- C:\BOOTSECT.DOS
[2010/12/14 20:47:03 | 000,014,465 | ---- | M] () -- C:\ComboFix.txt
[2002/09/03 10:36:02 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2004/05/13 20:52:28 | 000,005,751 | RH-- | M] () -- C:\DELL.SDR
[2010/12/16 22:05:30 | 535,875,584 | -HS- | M] () -- C:\hiberfil.sys
[2002/09/03 10:36:02 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2010/12/15 17:57:12 | 000,000,550 | ---- | M] () -- C:\ipconfig_all.txt
[2008/11/25 05:25:43 | 000,004,586 | -H-- | M] () -- C:\IPH.PH
[2010/12/16 21:14:35 | 000,001,857 | ---- | M] () -- C:\JavaRa.log
[2002/09/03 10:36:02 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
[2008/04/13 23:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/04/13 23:00:00 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/12/16 22:05:28 | 805,306,368 | -HS- | M] () -- C:\pagefile.sys
[2010/12/10 12:38:06 | 000,053,490 | ---- | M] () -- C:\TDSSKiller.2.4.11.0_10.12.2010_12.36.40_log.txt
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/12/04 18:39:41 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\DESKTOP.INI
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/09 10:23:54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\mdippr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/12/04 09:12:42 | 000,524,288 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\default.sav
[2010/11/30 08:08:30 | 000,057,344 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\security.sav
[2010/12/04 09:12:42 | 031,838,208 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\software.sav
[2010/12/04 09:12:42 | 006,262,784 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/12/04 18:40:18 | 000,000,294 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2009/08/13 07:11:17 | 000,018,533 | ---- | M] () -- C:\WINDOWS\SYSTEM32\ewab.db
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/12/04 19:31:02 | 000,000,177 | -HS- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI
[2004/05/19 04:15:40 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2004/02/20 12:11:12 | 000,050,688 | ---- | M] (Atribune.org) -- C:\Documents and Settings\Samuel M. Saunders\Desktop\ATF-Cleaner.exe
[2010/12/13 11:43:58 | 003,989,182 | R--- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\ComboFix.exe
[2010/12/07 11:07:38 | 000,132,597 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Flash_Disinfector.exe
[2010/12/10 11:49:50 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\MBRCheck.exe
[2010/12/16 20:49:45 | 000,924,816 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Norton_Removal_Tool.exe
[2010/12/06 14:39:26 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Samuel M. Saunders\Desktop\OTL.exe
[2010/12/06 14:44:32 | 000,296,448 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\r86rzteq.exe
[2010/12/08 14:48:08 | 001,344,600 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Samuel M. Saunders\Desktop\TDSSKiller.exe
[2010/12/07 11:03:32 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Samuel M. Saunders\Desktop\TFC.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2010/12/04 19:31:04 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2008/12/18 14:34:04 | 000,000,067 | -HS- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Cookies\desktop.ini
[2010/12/16 22:05:45 | 000,032,768 | -HS- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
[2004/08/10 21:45:04 | 000,192,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\INF\unregmp2.exe
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
[2002/12/17 07:23:22 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\lvback.gif
[2002/12/17 07:23:28 | 000,000,807 | ---- | M] () -- C:\Program Files\Messenger\mailtmpl.txt
[2002/08/20 12:08:38 | 000,069,663 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\MSMSGSIN.EXE
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
========== Files - Modified Within 30 Days ==========
[2010/12/16 22:29:02 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/16 22:05:50 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/16 22:05:46 | 000,001,192 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2010/12/16 22:05:31 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2010/12/16 22:05:30 | 535,875,584 | -HS- | M] () -- C:\hiberfil.sys
[2010/12/16 21:48:01 | 000,001,030 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1380815714-836596746-3658294935-1008UA.job
[2010/12/16 21:12:17 | 000,205,540 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\JavaRa.zip
[2010/12/16 20:49:45 | 000,924,816 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Norton_Removal_Tool.exe
[2010/12/16 20:48:01 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1380815714-836596746-3658294935-1008Core.job
[2010/12/16 20:45:32 | 000,002,361 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/12/16 20:45:31 | 000,002,383 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Google Chrome.lnk
[2010/12/16 18:33:02 | 000,018,944 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\Kingdoms.xls
[2010/12/15 20:14:26 | 000,000,595 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WNA3100 Smart Wizard.lnk
[2010/12/15 20:14:26 | 000,000,583 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\NETGEAR WNA3100 Smart Wizard.lnk
[2010/12/14 20:42:46 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\ETC\hosts
[2010/12/13 11:43:58 | 003,989,182 | R--- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\ComboFix.exe
[2010/12/10 21:22:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/12/10 11:49:50 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\MBRCheck.exe
[2010/12/10 11:49:06 | 001,230,779 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\tdsskiller.zip
[2010/12/08 14:48:08 | 001,344,600 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Samuel M. Saunders\Desktop\TDSSKiller.exe
[2010/12/07 21:27:23 | 000,040,960 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Avira AntiVir Personal.doc
[2010/12/07 11:07:38 | 000,132,597 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Flash_Disinfector.exe
[2010/12/07 11:03:32 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Samuel M. Saunders\Desktop\TFC.exe
[2010/12/06 14:44:32 | 000,296,448 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\r86rzteq.exe
[2010/12/06 14:39:26 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Samuel M. Saunders\Desktop\OTL.exe
[2010/12/06 11:26:06 | 000,002,473 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\HiJackThis.lnk
[2010/12/04 19:27:34 | 000,273,376 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/04 18:49:12 | 000,000,316 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2010/12/04 18:38:23 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2010/12/04 17:48:43 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2010/12/04 17:25:59 | 000,004,444 | ---- | M] () -- C:\WINDOWS\System32\pid.PNF
[2010/12/04 17:25:48 | 000,422,722 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
[2010/12/04 17:25:48 | 000,071,186 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
[2010/11/29 17:42:18 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/11/22 16:49:27 | 000,271,360 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\contacts.pst
[1 C:\Documents and Settings\Samuel M. Saunders\*.tmp files -> C:\Documents and Settings\Samuel M. Saunders\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/16 21:12:31 | 000,205,540 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\JavaRa.zip
[2010/12/16 20:52:56 | 000,924,816 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Norton_Removal_Tool.exe
[2010/12/16 20:45:32 | 000,002,361 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/12/16 20:45:31 | 000,002,383 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Google Chrome.lnk
[2010/12/16 20:43:37 | 000,001,030 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1380815714-836596746-3658294935-1008UA.job
[2010/12/16 20:43:36 | 000,000,978 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1380815714-836596746-3658294935-1008Core.job
[2010/12/15 20:14:26 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2010/12/15 20:14:26 | 000,000,595 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WNA3100 Smart Wizard.lnk
[2010/12/15 20:14:26 | 000,000,583 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\NETGEAR WNA3100 Smart Wizard.lnk
[2010/12/14 20:50:26 | 535,875,584 | -HS- | C] () -- C:\hiberfil.sys
[2010/12/13 18:24:07 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/12/13 18:24:07 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/12/13 18:24:07 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/12/13 18:24:07 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/12/13 18:24:07 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/12/13 18:18:09 | 003,989,182 | R--- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\ComboFix.exe
[2010/12/10 12:44:28 | 000,080,384 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\MBRCheck.exe
[2010/12/10 12:35:34 | 001,230,779 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\tdsskiller.zip
[2010/12/07 21:27:23 | 000,040,960 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Avira AntiVir Personal.doc
[2010/12/07 19:12:04 | 000,296,448 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\r86rzteq.exe
[2010/12/07 18:51:16 | 000,132,597 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Flash_Disinfector.exe
[2010/12/06 13:13:51 | 000,018,944 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xrxscnui.dll
[2010/12/06 13:13:48 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xrxftplt.exe
[2010/12/06 13:02:03 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2010/12/06 12:55:51 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2010/12/06 12:54:42 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2010/12/06 12:54:39 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2010/12/06 12:54:34 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2010/12/06 12:53:36 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2010/12/06 12:52:42 | 000,165,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt53.dll
[2010/12/06 12:52:38 | 000,093,696 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt42.dll
[2010/12/06 12:52:33 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt34.dll
[2010/12/06 12:52:28 | 000,089,088 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt33.dll
[2010/12/06 12:52:24 | 000,083,968 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt21.dll
[2010/12/06 12:52:07 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2010/12/06 12:51:28 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
[2010/12/06 12:49:19 | 000,029,768 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divasu.dll
[2010/12/06 12:49:18 | 000,037,962 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divaprop.dll
[2010/12/06 12:49:17 | 000,006,216 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divaci.dll
[2010/12/06 12:47:37 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2010/12/06 12:46:17 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atixbar.sys
[2010/12/06 12:46:16 | 000,026,624 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativxbar.sys
[2010/12/06 12:46:16 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativttxx.sys
[2010/12/06 12:46:15 | 000,009,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativmdcd.sys
[2010/12/06 12:46:14 | 000,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitvsnd.sys
[2010/12/06 12:46:14 | 000,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitunep.sys
[2010/12/06 12:46:13 | 000,049,920 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtcap.sys
[2010/12/06 12:46:13 | 000,026,880 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtsnd.sys
[2010/12/06 12:46:11 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atipcxxx.sys
[2010/12/06 12:46:04 | 000,046,464 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atibt829.sys
[2010/12/06 11:25:46 | 000,002,473 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\HiJackThis.lnk
[2010/12/04 17:25:59 | 000,004,444 | ---- | C] () -- C:\WINDOWS\System32\pid.PNF
[2010/12/04 17:25:09 | 000,144,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat
[2010/12/04 17:25:09 | 000,014,433 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn9.cat
[2010/12/04 17:25:08 | 000,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2010/12/04 17:25:08 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2010/12/04 17:25:08 | 000,112,918 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat
[2010/12/04 17:25:08 | 000,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2010/12/04 17:25:08 | 000,034,747 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat
[2010/12/04 17:25:08 | 000,034,063 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
[2010/12/04 17:25:08 | 000,026,991 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn7.cat
[2010/12/04 17:25:08 | 000,016,535 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
[2010/12/04 17:25:08 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2010/12/04 17:25:08 | 000,012,363 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2010/12/04 17:25:08 | 000,010,027 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2010/12/04 17:25:08 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2010/12/04 17:25:08 | 000,007,710 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2010/12/04 17:25:08 | 000,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat
[2010/12/04 17:25:07 | 002,144,487 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
[2010/12/04 17:25:07 | 001,296,669 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP3.CAT
[2010/12/04 17:25:07 | 000,522,220 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2009/09/28 04:02:05 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2009/08/13 07:11:17 | 000,019,350 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\kevik.bin
[2009/08/13 07:11:16 | 000,018,923 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Application Data\raqivyv._dl
[2009/08/13 07:11:16 | 000,013,308 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Application Data\lokafoje.bin
[2009/08/03 12:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/02/10 12:25:30 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2009/02/10 12:23:49 | 000,000,044 | ---- | C] () -- C:\WINDOWS\EPSNX400.ini
[2008/04/13 21:42:04 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2007/09/13 18:04:35 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MTB13GE.INI
[2007/02/23 16:52:26 | 000,002,508 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Application Data\$_hpcst$.hpc
[2007/01/10 05:18:18 | 000,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
[2006/07/03 04:25:16 | 000,000,036 | ---- | C] () -- C:\WINDOWS\webica.ini
[2005/12/26 16:54:59 | 000,001,787 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/12/16 08:51:15 | 000,000,387 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2005/11/01 10:06:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2005/02/10 10:17:50 | 000,172,056 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll
[2004/07/13 17:40:39 | 000,011,142 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
[2004/07/04 04:17:40 | 000,000,700 | ---- | C] () -- C:\WINDOWS\MTB13.INI
[2004/05/23 04:06:18 | 000,207,360 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/05/19 08:58:26 | 000,000,141 | ---- | C] () -- C:\Documents and Settings\Samuel M. Saunders\Local Settings\Application Data\fusioncache.dat
[2004/05/13 21:30:05 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/05/13 21:18:33 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/05/13 21:08:18 | 000,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2004/05/13 20:48:54 | 000,000,550 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/01/23 06:03:50 | 000,000,791 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
[2003/01/07 12:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/09/03 10:35:18 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[1979/12/31 21:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
========== LOP Check ==========
[2008/07/18 06:19:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bloomberg
[2009/02/10 12:36:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2010/08/20 09:02:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/12/14 19:15:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/20 17:46:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/06/25 03:09:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/23 06:22:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/06/18 12:40:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/08/20 07:29:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Samuel M. Saunders\Application Data\Aim
[2006/05/13 05:11:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Samuel M. Saunders\Application Data\ICAClient
[2010/08/20 08:12:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Samuel M. Saunders\Application Data\Juniper Networks
[2005/09/02 06:29:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Samuel M. Saunders\Application Data\Leadertech
[2010/12/14 19:15:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Samuel M. Saunders\Application Data\Viewpoint
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2002/09/03 10:36:02 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010/12/04 17:48:43 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2002/09/03 10:13:28 | 000,000,512 | -HS- | M] () -- C:\BOOTSECT.DOS
[2010/12/14 20:47:03 | 000,014,465 | ---- | M] () -- C:\ComboFix.txt
[2002/09/03 10:36:02 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2004/05/13 20:52:28 | 000,005,751 | RH-- | M] () -- C:\DELL.SDR
[2010/12/16 22:05:30 | 535,875,584 | -HS- | M] () -- C:\hiberfil.sys
[2002/09/03 10:36:02 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2010/12/15 17:57:12 | 000,000,550 | ---- | M] () -- C:\ipconfig_all.txt
[2008/11/25 05:25:43 | 000,004,586 | -H-- | M] () -- C:\IPH.PH
[2010/12/16 21:14:35 | 000,001,857 | ---- | M] () -- C:\JavaRa.log
[2002/09/03 10:36:02 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
[2008/04/13 23:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/04/13 23:00:00 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/12/16 22:05:28 | 805,306,368 | -HS- | M] () -- C:\pagefile.sys
[2010/12/10 12:38:06 | 000,053,490 | ---- | M] () -- C:\TDSSKiller.2.4.11.0_10.12.2010_12.36.40_log.txt
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/12/04 18:39:41 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\DESKTOP.INI
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/09 10:23:54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\mdippr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/12/04 09:12:42 | 000,524,288 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\default.sav
[2010/11/30 08:08:30 | 000,057,344 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\security.sav
[2010/12/04 09:12:42 | 031,838,208 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\software.sav
[2010/12/04 09:12:42 | 006,262,784 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/12/04 18:40:18 | 000,000,294 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2009/08/13 07:11:17 | 000,018,533 | ---- | M] () -- C:\WINDOWS\SYSTEM32\ewab.db
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/12/04 19:31:02 | 000,000,177 | -HS- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI
[2004/05/19 04:15:40 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2004/02/20 12:11:12 | 000,050,688 | ---- | M] (Atribune.org) -- C:\Documents and Settings\Samuel M. Saunders\Desktop\ATF-Cleaner.exe
[2010/12/13 11:43:58 | 003,989,182 | R--- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\ComboFix.exe
[2010/12/07 11:07:38 | 000,132,597 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Flash_Disinfector.exe
[2010/12/10 11:49:50 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\MBRCheck.exe
[2010/12/16 20:49:45 | 000,924,816 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\Norton_Removal_Tool.exe
[2010/12/06 14:39:26 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Samuel M. Saunders\Desktop\OTL.exe
[2010/12/06 14:44:32 | 000,296,448 | ---- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Desktop\r86rzteq.exe
[2010/12/08 14:48:08 | 001,344,600 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Samuel M. Saunders\Desktop\TDSSKiller.exe
[2010/12/07 11:03:32 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Samuel M. Saunders\Desktop\TFC.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2010/12/04 19:31:04 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2008/12/18 14:34:04 | 000,000,067 | -HS- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Cookies\desktop.ini
[2010/12/16 22:05:45 | 000,032,768 | -HS- | M] () -- C:\Documents and Settings\Samuel M. Saunders\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
[2004/08/10 21:45:04 | 000,192,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\INF\unregmp2.exe
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
[2002/12/17 07:23:22 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\lvback.gif
[2002/12/17 07:23:28 | 000,000,807 | ---- | M] () -- C:\Program Files\Messenger\mailtmpl.txt
[2002/08/20 12:08:38 | 000,069,663 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\MSMSGSIN.EXE
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >